CVE-2026-59706: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f
Unauthenticated users can steal LLM API keys and pivot into internal networks via SSRF.

1 CRIT · 4 HIGH · 1 MED · 1 INFO · THREAT RED · 7 items · Generated in 183s
Unauthenticated users can steal LLM API keys and pivot into internal networks via SSRF.
Oversized audio uploads can exhaust memory and crash or degrade exposed vLLM transcription services before limits are enforced.
Remote requests can crash the shared vLLM worker, causing service-wide denial of service until restart.
An authorized remote user can crash the whole vLLM server with one request, causing denial of service until it is restarted or fixed.
A single malicious regex can hang a vLLM inference worker and cause denial of service until the service is patched.
Weak hashing in LangGraph task caching can let remote attackers cause cache collisions or integrity issues in affected versions.
Shows prompt injection resistance improved, but it does not remove the need for hard boundaries around secrets and actions.